US2025132927A1PendingUtilityA1

Method for authenticatable data transmission

Assignee: UBLOX AGPriority: Oct 24, 2023Filed: Oct 23, 2024Published: Apr 24, 2025
Est. expiryOct 24, 2043(~17.2 yrs left)· nominal 20-yr term from priority
H04L 9/0825H04L 9/3236H04L 9/3247H04L 9/3242H04L 9/3073H04L 9/16H04L 9/0822H04L 2209/601H04L 9/3252H04L 9/088
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for authenticatable data transmission via a one-to-many communication channel from a provider device to a receiver device. A first key pair comprising a first private key and a first public key and supporting bilinear pairings as well as one or more second key pairs are generated and stored. Each second key pair comprises a respective second private key and a respective second public key and supporting bilinear pairings. One or more messages of a first type are obtained and a respective hash is generated for each of them. An authentication message is composed including the generated hashes. The composed authentication message is signed employing the first private key for producing a signed aggregated authentication message, which is distributed to the receiver device.

Claims

exact text as granted — not AI-modified
1 . A method for authenticatable data transmission via a one-to-many communication channel from a provider device to a receiver device, the method comprising
 obtaining, by the provider device (PD), a first key pair comprising a first private key and a first public key and supporting bilinear pairings, in particular asymmetric bilinear pairings, based on a first generator P selected from a first cyclic group G 1  of a first order q and on a second generator Q selected from a second cyclic group G 2  of the first order q, wherein the first private key is based on a random number in an interval [0;q−1] and the first public key is computed using the second generator Q and the first private key;   obtaining, by the provider device, one or more second key pairs, each comprising a respective second private key and a respective second public key and supporting bilinear pairings, in particular asymmetric bilinear pairings, based on a second order q′ smaller than the first order q;   providing the first public key to the receiver device;   selecting, by the provider device, one of the one or more second key pairs;   obtaining, by the provider device, one or more messages of a first type;   generating, by the provider device, a respective hash for each of the one or more messages of the first type;   composing, by the provider device, an authentication message including the generated hashes and either the second public key of the selected second key pair or data adapted for deriving the second public key of the selected second key pair;   signing, by the provider device, the composed authentication message employing the first private key for producing a signed aggregated authentication message;   distributing, by the provider device via the one-to-many communication channel, the signed aggregated authentication message to the receiver device;   after distributing the signed aggregated authentication message, distributing, by the provider device via the one-to-many communication channel, the one or more messages of the first type to the receiver device;   after distributing the signed aggregated authentication message, obtaining, by the provider device, one or more messages of a second type;   signing, by the provider device, the one or more messages of the second type employing the second private key of the selected second key pair for creating an associated signature; and   distributing, by the provider device via the one-to-many communication channel, the one or more messages of the second type together with the associated signature to the receiver device.   
     
     
         2 . The method according to  claim 1 , further comprising
 authenticating, by the receiver device, the signed aggregated authentication message employing the first public key;   authenticating, by the receiver device, the one or more messages of the first type employing the respective hashes distributed with the signed aggregated authentication message;   deriving, by the receiver device, the second public key of the selected second key pair from the signed aggregated authentication message; and   authenticating, by the receiver device, the one or more messages of the second type employing the associated signature and the derived second public key of the selected second key pair.   
     
     
         3 . The method according to  claim 1 , further comprising
 encrypting each second public key of a subset of the one or more second key pairs with a dedicated symmetric security key; and   providing the encrypted second public keys to the receiver device, in particular before generating the messages of the second type; wherein   the authentication message is selectively either composed with the second public key of the selected second key pair or the data adapted for deriving the second public key of the selected second key pair; and   the data comprise a nonce and the dedicated symmetric security key for the decryption of the encrypted second public key.   
     
     
         4 . The method according to  claim 1 , wherein
 the first key pair is generated, by the provider device or a trusted entity, repeatedly with a first repetition rate and subsequently stored in the provider device, each generated first key pair distinguishing from the first key pair of a preceding repetition; and   selecting the one of the one or more second key pairs is performed with a second repetition rate that is higher than the first repetition rate, in particular by a factor of at least  100 , each selected second key pair distinguishing from any selected second key pair of preceding repetitions.   
     
     
         5 . The method according to  claim 4 , wherein
 if obtaining the one or more second key pairs consists of obtaining a single second key pair, obtaining the one or more second key pairs and selecting the one of the one or more second key pairs is performed with the second repetition rate; and   if obtaining the one or more second key pairs consists of obtaining more than one second key pair, selecting the one of the one or more second key pairs is performed with the second repetition rate and obtaining the one or more second key pairs is performed with the first repetition rate or with a third repetition rate that is higher than the first repetition rate and lower than the second repetition rate.   
     
     
         6 . The method according to  claim 1 , wherein signing the composed authentication message and/or signing the one or more messages of the second type is based on a short signature scheme, in particular using a pairing-friendly Barreto-Naehrig curve or Barreto-Lynn-Scott curve, the short signature scheme producing respective signatures corresponding to a respective single elliptic curve point. 
     
     
         7 . The method according to  claim 6 , wherein signing the composed authentication message and/or signing the one or more messages of the second type is based on a Type-III pairing scheme defined as:
   { q, G   1   , G   2   , G   T   , e:G   1   ×G   2   →G   T   , P∈G   1   , Q∈G   2   , H:{ 0,1 }*→Z   q },   
       wherein Gr is a multiplicative paired group, H defines a cryptographic hash function for generating a field Z q , x is a private key selected randomly from the field Z q , and wherein a signature S for a message m is computed according to 
       
         
           
             
               S 
               = 
               
                 
                   
                     1 
                     
                       
                         H 
                         ⁡ 
                         ( 
                         m 
                         ) 
                       
                       + 
                       x 
                     
                   
                   · 
                   P 
                 
                 ∈ 
                 
                   
                     G 
                     1 
                   
                   . 
                 
               
             
           
         
       
     
     
         8 . The method according to  claim 1 , wherein the hashes are generated based on an intermediate key derived from at least parts of the composed authentication message. 
     
     
         9 . The method according to  claim 1 , wherein each hash is a keyed hashed message authentication code. 
     
     
         10 . The method according to  claim 8 , wherein the composed authentication message further includes a control section including information on at least one of
 a key to be used for generating the hashes;   a hash function to be used for generating the hashes;   a number of rounds to be used for generating the hashes;   a truncation level to be used for generating the hashes.   
     
     
         11 . A computer program product comprising instructions which, when executed on two or more processors of at least a provider device and a receiver device, cause the two or more processors to perform the method according to  claim 1 . 
     
     
         12 . A provider device for a one-to-many communication network, wherein
 a first key pair comprising a first private key and a first public key and supporting bilinear pairings, in particular asymmetric bilinear pairings, is generated by the provider device or a trusted entity based on a first generator P selected from a first cyclic group G 1  of a first order q and on a second generator Q selected from a second cyclic group G 2  of the first order q, wherein the first private key is based on a random number in an interval [0;q−1] and the first public key is computed using the second generator Q and the first private key;   the first public key is provided to a receiver device;   one or more second key pairs, each comprising a respective second private key and a respective second public key and supporting bilinear pairings, in particular asymmetric bilinear pairings, based on a second order q′ smaller than the first order q are generated by the provider device or the trusted entity;   the provider device being configured to   obtain the first key pair and the one or more second key pairs;   obtain one or more messages of a first type;   select one of the one or more second key pairs;   generate a respective hash for each of the one or more messages of the first type;   compose an authentication message including the generated hashes and either the second public key of the selected second key pair or data adapted for deriving the second public key of the selected second key pair;   sign the composed authentication message employing the first private key for producing a signed aggregated authentication message;   distribute, via a one-to-many communication channel, the signed aggregated authentication message to the receiver device;   distribute, via the one-to-many communication channel after distributing the signed aggregated authentication message, the one or more messages of the first type to the receiver device;   obtain, after distributing the signed aggregated authentication message, one or more messages of a second type;   sign the one or more messages of the second type employing the second private key of the selected second key pair for creating an associated signature; and   distribute, via the one-to-many communication channel, the one or more messages of the second type together with the associated signature to the receiver device.   
     
     
         13 . The provider device according to  claim 12 , wherein
 each second public key of a subset of the plurality of second key pairs is encrypted with a dedicated symmetric security key and distributed to the receiver device, in particular before the messages of the second type are generated;   the authentication message is selectively either composed with the second public key of the selected second key pair or the data adapted for deriving the second public key of the selected second key pair; and   the data comprise a nonce and the dedicated symmetric security key for the second public key.   
     
     
         14 . A receiver device for a one-to-many communication network, wherein
 a first key pair comprising a first private key and a first public key and supporting bilinear pairings, in particular asymmetric bilinear pairings, is generated by a provider device or a trusted entity based on a first generator P selected from a first cyclic group G 1  of a first order q and on a second generator Q selected from a second cyclic group G 2  of the first order q, wherein the first private key is based on a random number in an interval [0;q−1] and the first public key is computed using the second generator Q and the first private key;   the first public key is provided to the receiver device;   one or more second key pairs, each comprising a respective second private key and a respective second public key and supporting bilinear pairings, in particular asymmetric bilinear pairings, based on a second order q′ smaller than the first order q are generated by the provider device or the trusted entity;   one or more messages of a first type are obtained by the provider device;   one of the one or more second key pairs is selected by the provider device;   a respective hash is generated by the provider device for each of the one or more messages of the first type;   an authentication message is composed by the provider device including the generated hashes and either the second public key of the selected second key pair or data adapted for deriving the second public key of the selected second key pair;   the composed authentication message is signed by the provider device employing the first private key for producing a signed aggregated authentication message;   one or more messages of a second type are obtained by the provider device;   the one or more messages of the second type are signed by the provider device employing the second private key of the selected second key pair for creating an associated signature;   the receiver device being configured to   store the first public key;   receive, from the provider device via a one-to-many communication channel, the signed aggregated authentication message;   authenticate the signed aggregated authentication message employing the first public key;   derive the second public key of the selected second key pair from the signed aggregated authentication message;   receive, from the provider device via the one-to-many communication channel, the one or more messages of the first type;   authenticate the one or more messages of the first type employing the respective hashes distributed with the signed aggregated authentication message;   receive, from the provider device via the one-to-many communication channel, the one or more messages of the second type together with the associated signature; and   authenticate the one or more messages of the second type employing the associated signature and the derived second public key of the selected second key pair.   
     
     
         15 . A communication system for a one-to-many communication network, the communication system comprising a provider device according to  claim 12 . 
     
     
         16 . A communication system for a one-to-many communication network. the communication system comprising a receiver device according to  claim 14 .

Join the waitlist — get patent alerts

Track US2025132927A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.